Skip to content

Engine on Render

Render runs the engine image as a web service. The free instance type works for a demo or a staging engine.

  • A Render account.
  • A Postgres database. On Supabase or Neon, use the connection string each page recommends.
  1. Create a web service that deploys an existing image, and enter ghcr.io/lyeve-labs/lyeve-core:latest. Pin a release tag in production. See Docker images.
  2. Choose the API with PORT. Render sends traffic to the port PORT names, and the image's built-in health check probes that port too. PORT=3001 publishes the Admin API, which you need to create the first administrator and define content types. PORT=3002 publishes the Content API for your sites and apps.

Do not run a second Render service from the image for the other port. Each service creates its own signing key, so a token issued by one is refused by the other.

Set these in the service's environment:

DATABASE_URL=postgres://<user>:<password>@<host>:5432/<dbname>?sslmode=require
DATABASE_MAX_CONNECTIONS=5
JWT_SECRET=<openssl rand -hex 32>
ENCRYPTION_KEY=<a different openssl rand -hex 32>
LYEVE_AUDIT_HMAC_KEY=<a third openssl rand -hex 32>
RATE_LIMIT_RPS=100
SECURE_COOKIE=true
CORS_ORIGINS=https://your-app.example.com
PORT=3001

Production refuses to start without these values. Configuration lists every check.

Free Postgres plans have tight connection limits, and an engine that restarts after every spin-down reconnects each time, so keep DATABASE_MAX_CONNECTIONS small. Supported databases lists the URL forms.

Set the service's health check path to /readyz. Both listeners serve /healthz, /readyz and /startup without authentication. Do not use /api/admin/health or /api/v1/health: they need authentication, so a check gets 401 and marks a healthy service down. Health endpoints says what each one checks.

With PORT=3001:

Terminal window
curl https://your-service.onrender.com/api/admin/setup

A new install answers {"setup_required":true,"token_source":"log"}. The setup token is the one-time setup_token in the service's log, or LYEVE_SETUP_TOKEN when you set it. The quickstart continues from step 2.

With PORT=3002:

Terminal window
curl https://your-service.onrender.com/.well-known/jwks.json

The first request after idle time is slow, and the next ones are fast until the service spins down again.